GEO My WP SQL Injection Vulnerability in Proximity Search Function

Vulnerability

A SQL injection vulnerability has been identified in the GEO My WP plugin for WordPress, affecting versions through 4.5.4. The issue arises in the proximity search feature, where the 'distance', 'lat', and 'lng' parameters are improperly sanitized. The vulnerability allows attackers to inject malicious SQL payloads that could be executed by the database, potentially leading to unauthorized data access or manipulation.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker can manipulate database queries. This could lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the WordPress site.

Reproduction

To reproduce this vulnerability, send a request to a WordPress site with the GEO My WP plugin installed, using the 'distance', 'lat', or 'lng' parameters. The injected SQL payloads can be crafted to exploit the SQL injection vulnerability by, for example, using '1 OR SLEEP(3)' to test for SQL injection availability.

Remediation

Users are advised to update the GEO My WP plugin to version 4.5.5 or later, where this vulnerability has been patched.

Added: Jul 10, 2026, 5:36 AM
Updated: Jul 10, 2026, 5:36 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.4
remediation
0.0
relevance
9.3
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.